Information processing device and program
The information processing apparatus and program address the risk of unmanaged users staying logged in by identifying and logging out managed terminals, ensuring secure management transitions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-02
- Publication Date
- 2026-04-01
AI Technical Summary
When an unmanaged user gains access to a network system under the management of an administrator, there is a risk of the user remaining unmanaged after the administrator logs out, posing a security risk.
An information processing apparatus and program that identifies managed terminals used by unmanaged users and logs them out when a predetermined operation is performed by an administrator, optionally specifying another management user to take over the management.
Prevents unmanaged users from remaining logged in after the administrator logs out, ensuring secure management transitions and preventing unauthorized access.
Smart Images

Figure 0007838235000001 
Figure 0007838235000002 
Figure 0007838235000003
Abstract
Description
Technical Field
[0005]
[0001] The present invention relates to an information processing apparatus and a program.
Background Art
[0002] In recent years, cases where large companies collaborate with startup companies or freelancers to conduct business are on the rise. In this case, it may be preferable in terms of work efficiency for engineers of startup companies or the like collaborating with large companies to visit the large companies and network-connect the brought-in terminal devices to the in-house systems of the large companies so that they can work together as a team.
[0003] However, on the other hand, the security of companies tends to be strengthened, and there are many cases where the company's network system is operated so that outsiders cannot easily log in.
[0004] On the premise of such a system environment of a corporate network, when an outsider, that is, a user whose login to the network system is not permitted, is to be logged in and allowed to participate in the network system, the system administrator of the company may, for example, consider that the participation of the outsider in the network system may be permitted if the employee of the company collaborating with the outsider becomes a management user who participates in the network together with the outsider and constantly monitors the outsider while participating in the network system.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, when a managed user is logged into a network system under the management of an administrator, it is a security risk to leave the managed user logged into the network system after the administrator leaves the network system and the managed user is no longer under the administrator's management.
[0007] The present invention aims to prevent a user from remaining unmanaged when, in a situation where an unmanaged user who is not permitted to log in to a network system is logged in to the network system under the management of an administrator who is permitted to log in to the network system, the unmanaged user is removed from the administrator's management. [Means for solving the problem]
[0008] The information processing apparatus according to the present invention comprises a processor, which, under the management of an administrator user authorized to log in to a network system, identifies a managed terminal used by an unmanaged user who is not authorized to log in to the network system when the managed terminal is logged into the network system, in response to a predetermined operation by the administrator user, identifies a managed terminal to be logged out from among the managed terminals used by the unmanaged user under the administrator user's management, and logs out the identified managed terminal from the network system. If the predetermined operation is an operation in which the network system requests a logout from the management terminal used by the management user, and another management user is specified in the logout request, the management user of the managed user who was under the management of the management user that is being logged out will be changed to the other management user, thereby preventing the managed terminal used by the managed user from being logged out. It is characterized by the following:
[0011] The information processing apparatus according to the present invention comprises a processor, and under the management of an administrator user authorized to log in to a network system, when a managed terminal used by an unmanaged user who is not authorized to log in to the network system is logged into the network system, the processor, in response to a predetermined operation by the administrator user, will log out one of the managed terminals used by an unmanaged user under the management of the administrator user. Identify the managed terminal and log out the identified managed terminal from the network system. height, The predetermined operation but , an operation to request a logout specifying the location information of the management terminal used by the aforementioned management user. In the case of, The system is characterized by identifying managed terminals located at a predetermined distance from the management terminal as targets for logout in response to the logout request.
[0012] Furthermore, the processor is characterized in that, after receiving the logout request, it identifies the managed terminal located at a predetermined distance from the management terminal as the target for logout.
[0017] The program according to the present invention provides a computer with the following functions: when a managed terminal used by an unmanaged user who is not permitted to log in to the network system is logged into the network system under the management of an administrator user who is permitted to log in to the network system, the administrator user will, in response to a predetermined operation by the administrator user, identify an unmanaged terminal to be logged out from among the unmanaged terminals used by the unmanaged user under the administrator user's management, and log out the identified unmanaged terminal from the network system; If the predetermined operation is an operation in which the network system requests a logout from the management terminal used by the management user, and another management user is specified in the logout request, the function prevents the managed terminal used by the managed user from being logged out by changing the management user of the managed user who was under the management of the management user who is logging out to the other management user. To make it happen. The program according to the present invention enables a computer to perform the following functions in response to a predetermined operation by an administrator user who is authorized to log in to a network system, when an administrator user who is authorized to log in to a network system has a managed terminal used by an unmanaged user who is not authorized to log in to the network system logged into the network system: identify an unmanaged terminal to be logged out from among the unmanaged terminals used by an unmanaged user under the management of the administrator user; log out the identified unmanaged terminal from the network system; and, if the predetermined operation is an operation that specifies the location information of the administrator terminal used by the administrator user to log out, identify an unmanaged terminal that is a predetermined distance away from the administrator terminal as the target for logout in response to the logout request. [Effects of the Invention]
[0018] Claim 1, 4 According to the invention described above, when a managed user who is not permitted to log in to the network system is logged in to the network system under the management of a manager who is permitted to log in to the network system, if the managed user is removed from the manager's management, it is possible to prevent the managed user from remaining in an unmanaged state. Furthermore, the managed terminal can be logged out in conjunction with the management terminal's logout. In addition, it is possible to avoid forcibly logging out the managed terminal.
[0021] Claim 2 According to the invention described, If an unmanaged user who is not authorized to log in to the network system is logged in to the network system under the management of an administrator who is authorized to log in to the network system, and the unmanaged user is removed from the administrator's management, it is possible to prevent the unmanaged user from remaining unmanaged. It is possible to forcibly log out managed devices that are located a predetermined distance from the management terminal.
[0022] Claim 3 According to the invention described above, if a managed terminal moves a predetermined distance away from the management terminal after receiving a logout request, the managed terminal can be logged out. [Brief explanation of the drawing]
[0027] [Figure 1] It is a block configuration diagram of the network system in Embodiment 1. [Figure 2] It is a diagram showing an example of the connection mid-terminal table in Embodiment 1. [Figure 3] It is a diagram showing an example of the access point management table in Embodiment 1. [Figure 4] It is a sequence diagram showing the logout process in Embodiment 1. [Figure 5] It is a block configuration diagram of the network system in Embodiment 2. [Figure 6] It is a diagram showing an example of the beacon management table in Embodiment 2. [Figure 7] It is a diagram showing an example of the room information table in Embodiment 2. [Figure 8] It is a sequence diagram showing the logout process in Embodiment 2. [Figure 9] It is a block configuration diagram showing the authentication system in Embodiments 3 and 4. [Figure 10] It is a sequence diagram showing the logout process in Embodiment 3. [Figure 11] It is a sequence diagram showing the logout process in Embodiment 4. [Figure 12] It is a block configuration diagram showing the authentication system in Embodiment 5. [Figure 13] It is a sequence diagram showing the logout process in Embodiment 5.
Embodiments for Carrying out the Invention
[0028] Hereinafter, preferred embodiments of the present invention will be described based on the drawings.
[0029] Embodiment 1. Figure 1 is a block diagram showing the authentication system in this embodiment. The authentication system in this embodiment is incorporated into a LAN (Local Area Network) system (hereinafter referred to as the "internal system") built within a company, and performs user authentication when a user joins the internal system network. The authentication system in this embodiment also handles the process when a user logs in and logs out of the internal system.
[0030] In this embodiment, the in-house system, as shown in Figure 1, is configured with an access point 2 installed in a room 1 within the company, a multifunction printer 3 and a repository 4 used by users of the in-house system, and an authentication server 10, all connected to LAN 5. Note that while Figure 1 shows the multifunction printer 3 and repository 4 as examples of equipment used by users of the in-house system, this is merely an example, and the number and types of each device are not limited to the system configuration example shown in Figure 1.
[0031] Room 1, illustrated in Figure 1, is a specific space accessible only to users authorized to log in to the company's internal systems. In other words, Room 1 forms a highly secure space within the facility, and not just anyone is allowed to enter. As mentioned above, Room 1 is a specific space accessible only to users authorized to log in to the company's internal systems; in other words, only trusted individuals are allowed to enter.
[0032] However, under the supervision of employees of collaborating companies, it is possible that individuals not authorized to log in to the internal system, such as external parties, may be permitted to enter Room 1 and, in fact, be authorized to log in to the internal system and actually do so.
[0033] If we refer to the employees of the collaborating companies as "managing users" who manage external parties, then external parties, despite not being authorized to log in to the internal system, are logged in under the management of the employees of the collaborating companies. Therefore, in this embodiment, they will be referred to as "managed users." Strictly speaking, users who are not authorized to log in to the internal system are those who cannot log in for reasons such as not having their personal information registered in the internal system, and who are not trusted. Therefore, even if they are not external parties, employees of the same company but at other business locations can be "managed users." On the other hand, users who are authorized to log in to the internal system are trusted users and may be in a position to manage managed users. Therefore, as in the higher-level model, they will be referred to as "managing users."
[0034] Here, the terms "login" and "logout" used in this embodiment will be explained.
[0035] Generally, "login" has various definitions, such as connecting a computer to a network or allowing a user to access a service. In this embodiment, "login" means network participation in the company's internal system, and is different from logging into a computer by specifying a user ID and password. Whether or not "login to the company's internal system is permitted" means whether or not one can connect to the company's internal system, in other words, whether or not one can participate in the company's internal network system. Furthermore, in this embodiment, "being logged into the company's internal system" means participating in the company's internal system via the network, or more specifically, being connected to access point 2 or the company's internal system. In the configuration of the company's internal system in this embodiment, terminals 30 and 40 are connected to the company's internal system via access point 2, so "being logged into the company's internal system" is equivalent to being connected to access point 2.
[0036] On the other hand, "logging out" means ceasing participation in the network. In other words, it means ceasing the connection with the internal system. In the configuration of the internal system in this embodiment, terminals 30 and 40 are connected to the internal system via access point 2, so "logging out of the internal system" for terminals 30 and 40 is equivalent to being disconnected from the connected access point 2.
[0037] Room 1 contains a management terminal 30 and managed terminals 40. The management terminal 30 is a terminal device used by the management user. The managed terminal 40 is a terminal device used by the managed user.
[0038] For the sake of explanation, within Room 1, the managing user will always carry one management terminal 30. Therefore, there is a one-to-one relationship between the managing user and the management terminal 30, and they will be located in the same place within Room 1. The same applies to the managed user who is being monitored; the managed user will always carry one managed terminal 40. Therefore, there is a one-to-one relationship between the managed user and the managed terminal 40, and they will be located in the same place within Room 1. Strictly speaking, the managing user is the one who monitors and manages the managed user, but from the perspective of the network system, it may also be explained that the management terminal 30 is the one who monitors and manages the managed terminal 40, given the relationship between the user and the terminal described above.
[0039] Furthermore, as defined above, "logout" means disconnecting terminals 30 and 40 from access point 2. However, since "logout" is performed according to instructions from the administrator, in the following explanation, for the sake of clarity, it may be written as "log out the administrator or the managed user," indicating that a user is being logged out. For example, logging out a managed user is equivalent to logging out the managed terminal 40 used by the managed user by disconnecting it from access point 2.
[0040] The management terminal 30 and the managed terminal 40 are portable information processing devices, as they are terminal devices that users bring into room 1. Examples include mobile PCs, tablet terminals, or smartphones. Each terminal 30 and 40 has a CPU, ROM, RAM, storage as a means of memory, a short-range wireless communication interface such as Wi-Fi (registered trademark) or BLE (Bluetooth (registered trademark) Low Energy) and a mobile communication interface as a means of communication, a touch panel, or a user interface including a mouse, keyboard, display, etc.
[0041] In this embodiment, the management terminal 30 has a logout request unit 31. The logout request unit 31 requests the authentication server 10 to log out of itself. The logout request unit 31 is realized through the cooperative operation of the computer forming the management terminal 30 and a program running on the CPU installed in the computer.
[0042] Access point 2 is a relay device that communicates wirelessly with communication devices located in room 1, namely terminals 30 and 40 mentioned above, and relays data communication between terminals 30 and 40 and the company's internal system. The location of the communication devices in room 1 is proven by communicating with access point 2 installed in room 1.
[0043] The authentication server 10 corresponds to the information processing device according to the present invention, forms the main part of the authentication system in this embodiment, and authenticates the user using the terminal from which the login request has been sent. The authentication server 10 also logs out terminals 30 and 40 that are to be logged out in response to a logout request from the management terminal 30. The authentication server 10 can be implemented with the hardware configuration of a conventional general-purpose server computer. That is, the authentication server 10 has a CPU, ROM, RAM, a hard disk drive (HDD) as a storage means, and a network interface provided as a communication means. In addition, a user interface including input means such as a mouse or keyboard and display means such as a display may be provided as needed.
[0044] The authentication server 10 includes a logout processing unit 11 and a storage unit 12. Components not used in the description of this embodiment are omitted from the diagram. For example, since this embodiment is characterized by its logout processing, components related to other user authentication and login processing are omitted from the diagram.
[0045] The managed terminal identification unit 111 identifies the managed terminal 40 to be logged out in response to a logout request from the management terminal 30. The disconnection instruction unit 112 instructs the access point 2 to disconnect from the terminals 30 and 40 to be logged out.
[0046] The memory unit 12 stores various types of information that can be represented in table format, as described below. In this embodiment, this information is stored in tables such as a connection management table and an access point management table.
[0047] Figure 2 shows an example of a connected terminal table in this embodiment. The connected terminal table registers the management terminal 30 connected to the internal system. The connected terminal table associates the management terminal with the managed terminals connected to the internal system under the management of the management user of the management terminal. The management terminal is associated with the terminal, user, IP address, and connecting AP. The terminal is set with a terminal ID as identification information for the management terminal 30 connected to the internal system. The user is set with a user ID as identification information for the management user using the management terminal 30. The IP address is set with the IP address assigned to the management terminal 30. The connecting AP is set with an access point ID as identification information for the access point 2 to which the management terminal 30 is wirelessly connected. The managed terminals are associated with the terminal, user, IP address, and connecting AP. The terminal is set with a terminal ID as identification information for the managed terminal 40 connected to the internal system. The user is set with a user ID as identification information for the managed user using the managed terminal 40. The IP address is set to the IP address assigned to the managed terminal 40. The connecting AP is set to the access point ID as identification information for the access point 2 to which the managed terminal 40 is wirelessly connected. Since the managed user is in the same room 1 as the managing user, meaning the connecting APs for the managing terminal and the managed user should be the same, this can be omitted. However, exceptional cases are possible, such as when multiple access points 2 are installed in the same room 1, so this is provided for both the managing terminal and the managed terminal. Note that, as illustrated with the managing terminal "X", the managing user may manage multiple managed users.
[0048] Figure 3 shows an example of an access point management table in this embodiment. The access point management table contains management information for access point 2 included in the company's internal system. The management information for access point 2 is set with an AP and an IP address associated with it. The AP is set with an access point ID as identification information for access point 2. The IP address is set with the IP address, which is the unique address information for access point 2.
[0049] The logout processing unit 11 is implemented through the coordinated operation of a computer forming the authentication server 10 and a program running on the CPU installed in that computer. The storage unit 12 is implemented using an HDD installed in the authentication server 10. Alternatively, RAM or storage means included in the company's internal system may be used via LAN 7.
[0050] Furthermore, the program used in this embodiment can be provided not only via communication means, but also stored on a computer-readable recording medium such as a CD-ROM or USB memory. The program provided via communication means or recording medium is installed on the computer, and various processes are realized by the computer's CPU executing the program sequentially.
[0051] Next, the operation in this embodiment will be described. In this embodiment, the managed user is assumed to be participating in the internal system network under the management of the managing user. That is, the managed terminal 40 is logged into the internal system. The same applies to the embodiments described below.
[0052] In this embodiment, the process for when an administrator user logs out of the internal system will be explained using the sequence diagram shown in Figure 4.
[0053] The logout request unit 31 in the management terminal 30 requests the authentication server 10 to log out of its own terminal in response to a predetermined operation by the management user (step 311). The access point 2 relays the logout request from the management terminal 30 to the authentication server 10, but since the relay function by the access point 2 is not a distinctive function, its explanation is omitted, and it is also omitted from the sequence diagram.
[0054] When a logout request is received, the managed terminal identification unit 111 in the authentication server 10 refers to the connected terminal table and identifies the managed terminal 40 that the management terminal 30 that sent the logout request is managing (step 111), and also identifies the access point 2 to which the identified managed terminal 40 is connected (step 112). According to the configuration example shown in Figure 2, it can be seen that the management terminal 30 with terminal ID "A" (hereinafter referred to as "management terminal A"; the same format is used for other devices) is managing managed terminal d1, and that managed terminal d1 is connected to access point AP3.
[0055] The above explanation did not explicitly state the information used to identify the source of the logout request. The authentication server 10 may identify the management terminal 30 that sent the logout request by referring to the header information of the data packet that makes up the logout request. Alternatively, the management terminal 30 may add its terminal ID or the user ID of the management user to the logout request it sends.
[0056] Next, the disconnection instruction unit 112 instructs the access point AP3 to disconnect the managed terminal d1 that is connected (step 113).
[0057] The disconnection processing unit 21 in access point AP3 disconnects the designated managed terminal d1 (step 211). As a result, managed terminal d1 is forcibly logged out of the company system by disconnecting its connection to access point AP3.
[0058] As described above, when the managed terminal d1 is logged out, the disconnection instruction unit 112 instructs access point AP3 to disconnect management terminal A in response to a request from management terminal A, which is the source of the logout request (step 114). The disconnection processing unit 21 in access point 2 logs out management terminal A by disconnecting it in response to this instruction (step 212).
[0059] According to this embodiment, when a logout request is received from the management terminal 30, the managed terminal 40 that the management terminal 30 manages is forcibly logged out. As a result, even if the administrator who manages the managed users leaves the network system, the managed users are logged out before the administrator leaves, thus preventing a situation where the administrator who manages the managed users is absent.
[0060] Embodiment 2. Figure 5 is a block diagram showing the authentication system in this embodiment. Components identical to those in the authentication system of Embodiment 1 shown in Figure 1 are denoted by the same reference numerals, and their descriptions are omitted as appropriate.
[0061] In this embodiment, a beacon 6 is installed in room 1. The beacon 6 is a transmitter that uses low-power short-range wireless communication technology (e.g., BLE) to wirelessly transmit location information that identifies the location of the device.
[0062] In this embodiment, the management terminal 30 has a location information acquisition unit 32 and a managed terminal logout request unit 33 instead of a logout request unit 31. The location information acquisition unit 32 acquires installation location information transmitted by the beacon 6. The managed terminal logout request unit 33 requests the authentication server 10 to log out the managed terminal 40 that is being managed. Each component 32 and 33 in the management terminal 30 is realized through the cooperative operation of the computer forming the management terminal 30 and the program running on the CPU installed in the computer.
[0063] In this embodiment, the managed terminal 40 has a location information transmission unit 41. The location information transmission unit 41 acquires installation location information transmitted by the beacon 6 in response to a request from the authentication server 10, and transmits this installation location information to the authentication server 10 as location information indicating the current location of the terminal. The location information transmission unit 41 is realized through the cooperative operation of the computer forming the managed terminal 40 and a program running on the CPU installed in the computer.
[0064] In addition to the configuration shown in Embodiment 1, the logout processing unit 11 in the authentication server 10 includes a location relationship determination unit 113. The location relationship determination unit 113 determines the location relationship between the management terminal 30 that sent the logout request and the managed terminal 40 of the managed user that the management user is managing. Specifically, it determines whether the managed terminal 40 is a predetermined distance away from the management terminal 30.
[0065] Furthermore, the storage unit 12 in this embodiment also stores a beacon management table and a room information table.
[0066] Figure 6 shows an example of a beacon management table in this embodiment. The beacon management table contains information for managing beacons 6 included in the company's internal system. For each beacon 6 included in the company's internal system, the management information for beacons 6 is set with the beacon, effective range, adjacent AP, and room number associated with it. A beacon ID is set as the identification information for the beacon 6. The effective range is set as the distance defined as the effective range of the wireless communication of the beacon 6. At least one access point 2 and one beacon 6 are installed in room 1, and the adjacent AP is set as the access point ID, which is the identification information for the access point 2 closest to the beacon 6. The room number is set as information that identifies the room 1 in which the beacon 6 is installed.
[0067] Figure 7 shows an example of a room information table in this embodiment. The room information table contains information about room 1 in which access point 2 and beacon 6 are installed in the company system. For each room 1, the room information is set with associated room number, beacon, AP, and map information. The room number is set as information that identifies the room 1. The beacon ID is set as identification information for beacon 6 installed in room 1. The access point ID is set as identification information for access point 2 installed in room 1. The map information contains spatial information that shows the characteristics of room 1. Details about the map information will be described later.
[0068] As mentioned above, the administrator needs to monitor the managed users to prevent any infringing actions, at least while they are in Room 1. To do this, the administrator wants the managed users to stay close to them. In other words, if the managed users move to a location that is out of the administrator's sight and are a certain distance away, there is a risk that they will no longer be able to be monitored, so this situation should be avoided. Therefore, in this embodiment, managed terminals 40 that are a certain distance away from the administrator terminal 30 are identified as targets for logout.
[0069] Next, the process for when an administrator logs out the managed terminal 40 from the internal system will be explained using the sequence diagram shown in Figure 8. Note that the same steps as in Embodiment 1 will be assigned the same step numbers, and explanations will be omitted as appropriate.
[0070] When a management user performs a predetermined logout request operation for a managed terminal 40 on the management terminal 30, the location information acquisition unit 32 acquires the installation location information transmitted by the beacon 6 (step 321). The installation location information includes the beacon ID. At this time, the location information acquisition unit 32 acquires the received signal strength at the time of information acquisition. Subsequently, the managed terminal logout request unit 33 uses the installation location information acquired by the location information acquisition unit 32 as location information indicating the current location of its own terminal, adds the received signal strength to that location information, and requests the authentication server 10 to log out the managed terminal 40 that is being managed (step 322).
[0071] Upon receiving a logout request, the managed terminal identification unit 111 in the authentication server 10 refers to the connected terminal table and identifies the managed terminal 40 that the management terminal 30 that sent the logout request is managing (step 111). Subsequently, the location relationship determination unit 113 requests the identified managed terminal 40 to transmit location information (step 121).
[0072] When the authentication server 10 sends a request to transmit location information, the location information transmission unit 41 acquires the installation location information transmitted by the beacon 6 (step 401). At this time, the location information transmission unit 41 acquires the received signal strength at the time of information acquisition. Subsequently, the location information transmission unit 41 uses the acquired installation location information as location information indicating the current location of its own terminal, adds the received signal strength to that location information, and transmits it to the authentication server 10 (step 402).
[0073] When location information is transmitted from the managed terminal 40 in response to a transmission request, the location relationship determination unit 113 compares the location information obtained from the management terminal 30 and the managed terminal 40. If the location information has the same beacon ID, the location relationship determination unit 113 determines that the management user and the managed user are in the same room 1, that is, the management user and the managed user are not far apart.
[0074] Furthermore, the position relationship determination unit 113 may also determine the positional relationship between the two in room 1. For example, the position relationship determination unit 113 obtains the effective distance of the beacon 6 from the acquired beacon ID by referring to the beacon management table. Then, the position relationship determination unit 113 converts the received signal strength obtained from the management terminal 30 and the managed terminal 40 into distance. The distance obtained by this conversion corresponds to the straight-line distance from beacon 6 to each terminal 30 and 40. Here, if the difference between each straight-line distance is less than or equal to a predetermined threshold, it is determined that the management user and the managed user are not far apart. In the above explanation, the determination was made using the beacon ID, but if the converted distance is within the effective distance, it may be determined that the terminals 30 and 40 are located in room 1 where the beacon 6 is installed.
[0075] By the way, if the distances between beacon 6 and each terminal 30 and 40 are d30 and d40 respectively, then logically, the management terminal 30 and the managed terminal 40 could be up to d30 + d40 apart. However, since the installation locations of the beacons in room 1 are fixed and known information, it is possible to more accurately determine the positional relationship between the two in room 1 by referring to the installation location of beacon 6 and setting an appropriate threshold value to compare with the difference in the above straight-line distances.
[0076] Next, the managed terminal identification unit 111 refers to the positional relationship determination result between the management terminal 30 and the managed terminal 40 by the positional relationship determination unit 113, identifies the managed terminal 40 used by a managed user that is determined to be a predetermined distance away from the management user, and refers to the connected terminal table to identify the access point 2 to which the identified managed terminal 40 is connected (step 112). Subsequently, the disconnection instruction unit 112 instructs the identified access point 2 to disconnect from the managed terminal 40 (step 123). Note that managed terminals 40 that are not a predetermined distance away from the management terminal 30 are not subject to logout.
[0077] The disconnection processing unit 21 at access point 2 disconnects the designated managed terminal 40 (step 211). As a result, the disconnected managed terminal 40 is forcibly logged out of the company system. In this embodiment, the management terminal 30 is not subject to logout.
[0078] According to this embodiment, a managed user who is a predetermined distance away from the managing user is presumed to be out of the managing user's sight and therefore unmanaged, and the managed terminal 40 is forcibly logged out.
[0079] In the process described above, a managed terminal 40 is forcibly logged out only when a logout request is received from the managing user. However, if the managed terminal 40 is located at a predetermined distance, it is preferable to forcibly log out that terminal at that point, or as soon as possible thereafter.
[0080] Therefore, for example, when the management terminal 30 receives the aforementioned forced logout instruction from the management user, it may periodically acquire installation location information from the beacon 6 and send a logout request (step 322) to the authentication server 10 until the instruction is canceled. Alternatively, when the authentication server 10 receives a logout request (step 322) from the management terminal 30, it may monitor whether the managed user has moved a predetermined distance away from the management user until the management terminal 30 sends a cancellation instruction or the management terminal 30 logs out, and when it finds a managed user that has moved a predetermined distance away, it may process the system to forcibly log out the corresponding managed terminal 40. In this way, after the authentication server 10 has received the logout request (step 322) from the managed terminal 40, it can identify managed terminals 40 that have moved a predetermined distance away from the management terminal 30 as targets for logout and forcibly log them out.
[0081] Furthermore, the above explanation assumes that the managed user moves away from the administrator, but it is also possible that the administrator moves and moves a predetermined distance away from the managed user. In this embodiment, even when the administrator moves, the managed user will end up in a location out of the administrator's sight, so the managed terminal 40 is logged out.
[0082] By the way, as explained above, in this embodiment, a beacon 6 is installed in room 1, and the installation location of the beacon 6 is used to identify the current location of each terminal 30, 40, or more precisely, the room 1 in which each terminal 30, 40 is located, in order to determine the relative positions of the terminals 30, 40.
[0083] However, if terminals 30 and 40 are equipped with a LiDAR (Light Detection And Ranging) scanner function, this LiDAR scanner function may be used. The "LiDAR scanner function" is a function that uses laser light to measure the distance to distant objects. Therefore, the user uses the LiDAR scanner function to measure the distance to their surroundings, that is, the distance to objects such as the walls, shelves, and furniture inside Room 1. The information that identifies the shape of the interior of Room 1 through this measurement is information unique to Room 1, and also spatial information that shows the characteristics of the space Room 1. The map information in the room information table shown in Figure 7 contains information that identifies the shape of the interior of Room 1.
[0084] Therefore, when spatial information acquired using the LiDAR scanner function is transmitted as location information from each terminal 30, 40, the location relationship determination unit 113 may identify the room 1 in which each terminal 30, 40 is located by comparing the spatial information acquired from each terminal 30, 40 by image analysis with the map information set in the room information table.
[0085] Furthermore, if terminals 30 and 40 are equipped with camera functions, it is possible to determine whether each terminal 30 or 40 is being used in room 1 in the same manner as with the LiDAR scanner function. In this case, the images captured by the cameras will become information indicating the current location of each terminal 30 or 40, and will be sent to the authentication server 10 as location information. In this case, the map information in the room information table shown in Figure 7 will be set with images of the interior of room 1.
[0086] Embodiment 3. Figure 9 is a block diagram showing the authentication system in this embodiment. Components identical to those in the authentication system of Embodiment 1 shown in Figure 1 are denoted by the same reference numerals, and their descriptions are omitted as appropriate. Similar to Embodiment 2, this embodiment includes a managed terminal logout request unit 33 that requests the authentication server 10 to log out the managed terminal 40. In Embodiment 2, the managed user logged out a managed terminal 40 used by a managed user located at a predetermined distance from the managed user. However, in this embodiment, the managed user explicitly specifies the managed terminal 40 to log out. The process for logging out a managed terminal 40 from the internal system will be described below using the sequence diagram shown in Figure 10. Components identical to those in Embodiments 1 and 2 are denoted by the same step numbers, and their descriptions are omitted as appropriate.
[0087] On the management terminal 30, the management user specifies the managed terminal 40 to be logged out from a predetermined logout request screen displayed on the screen, and then performs a predetermined logout request operation for the managed terminal 40. The managed terminal logout request unit 33 responds to this user operation by sending a logout request including the specified managed terminal 40 to the authentication server 10 (step 331). Strictly speaking, what is sent is the terminal ID that identifies the managed terminal 40. In the following description, as in this embodiment, the fact that identification information is sent will be omitted.
[0088] When specifying the managed terminals 40 to be logged out, the management terminal 30 may query the authentication server 10 in response to instructions from the management user to obtain a list of managed terminals 40 and display it as a list on the logout request screen. This allows the management user to specify the managed terminals 40 through a selection operation.
[0089] Upon receiving a logout request, the managed terminal identification unit 111 in the authentication server 10 refers to the connected terminal table and identifies the access point 2 to which the managed terminal 40 specified by the administrator user is connected (step 112).
[0090] Furthermore, the system may verify in advance the legitimacy of the managed terminal 40 specified by the administrator, that is, whether the administrator terminal 30 that initiated the logout request has the specified managed terminal 40 under its management. Alternatively, the administrator may specify a managed user instead of a managed terminal 40.
[0091] Next, the disconnection instruction unit 112 instructs the access point 2 identified by the managed terminal identification unit 111 to disconnect the managed terminal 40 designated by the management user (step 113).
[0092] The disconnection processing unit 21 at access point 2 disconnects the designated managed terminal 40 (step 211). As a result, the managed terminal 40 designated by the management user is forcibly logged out of the company system by having its connection to access point 2 severed.
[0093] According to this embodiment, by having the management user explicitly specify the managed terminal 40 to be logged out, the managed terminal 40 can be forcibly logged out.
[0094] Embodiment 4. In Embodiment 3 described above, the administrator explicitly specified the managed terminals 40 to be logged out. If the administrator wanted to log out all managed users under their management, they would have to specify each managed terminal 40 individually. If there are many managed users, this specification becomes cumbersome. Therefore, in this embodiment, the administrator's failure to specify managed users to be logged out is treated as specifying all managed users, and a logout request is sent for the managed terminals 40.
[0095] In this embodiment, the process for when a management user logs out the managed terminal 40 from the internal system will be explained using the sequence diagram shown in Figure 11. Note that the same steps as in the above embodiments will be assigned the same step numbers, and explanations will be omitted as appropriate.
[0096] The administrator user performs a predetermined logout request operation for a managed terminal 40 from a predetermined logout request screen displayed on the screen, without specifying the managed terminal 40 to be logged out. In response to this user operation, the managed terminal logout request unit 33 sends a logout request to the authentication server 10 in which the managed terminal 40 is not specified (step 331).
[0097] The managed terminal identification unit 111 in the authentication server 10 assumes that if a managed terminal 40 is not specified in the received logout request, the administrator has specified all managed terminals 40 that they manage as targets for logout. The managed terminal identification unit 111 then refers to the connected terminal table to identify all managed terminals 40 that the administrator manages (step 111), and identifies the access point 2 to which each managed terminal 40 is connected (step 112).
[0098] Next, the disconnection instruction unit 112 instructs the access point 2 identified by the managed terminal identification unit 111 to disconnect all managed terminals 40 that have been implicitly designated by the management user (step 113).
[0099] The disconnection processing unit 21 at access point 2 disconnects the designated managed terminal 40 (step 211). As a result, the managed terminal 40, implicitly designated by the management user, is forcibly logged out of the company system by having its connection to access point 2 severed.
[0100] According to this embodiment, if the managed terminal 40 is not specified in the logout request from the managed terminal 40, the authentication server 10 can assume that all managed terminals 40 to be managed have been specified and can forcibly log out all managed terminals 40 to be managed.
[0101] Embodiment 5. Figure 12 is a block diagram showing the authentication system in this embodiment. Components identical to those in the authentication system of Embodiment 1 shown in Figure 1 are denoted by the same reference numerals, and their descriptions are omitted as appropriate.
[0102] The logout processing unit 11 in the authentication server 10 has a management terminal change unit 114 in addition to the configuration shown in Embodiment 1. The management terminal change unit 114 is characterized by delegating the management of a managed user, which was under the management of the management user that made the logout request, to the other management user when another management user is specified in the logout request sent from the management terminal 30.
[0103] In the above embodiment 1, the managed users were forcibly logged out at the same time the managing user logged out. This was to prevent the managed user from being absent from the managed terminal 40. In other words, if the managed user of the managed terminal 40 is not absent, there is no need to forcibly log out the managed users.
[0104] Therefore, in this embodiment, if there is an administrator who manages the managed users that the administrator was managing on behalf of the administrator, the management of the managed users can be delegated to that administrator, so that the administrator logs out but the managed users do not have to log out.
[0105] Next, the process for when an administrator user logs out of the internal system will be explained using the sequence diagram shown in Figure 13. Note that the same steps as in the above embodiments will be assigned the same step numbers, and explanations will be omitted as appropriate.
[0106] On the management terminal 30, the management user specifies the management user to whom they will delegate the management of the managed user from a predetermined logout request screen displayed on the screen, and then performs a logout request operation for the predetermined managed terminal 40. The management user may specify the user ID of another management user, or the terminal ID of the management terminal 30 used by another management user. In response to this user operation, the managed terminal logout request unit 33 sends a logout request including the specified managed user to the authentication server 10 (step 331).
[0107] When the authentication server 10 receives a logout request sent from the management terminal 30, if the logout request specifies an administrator user, it determines that the logout request also serves as an administrator user change request. Alternatively, it may be determined to be an administrator user change request if the specified administrator user is different from the administrator user who sent the request. In this case, the management terminal change unit 114 confirms that the management terminal 30 used by the administrator user specified in the logout request is currently connected to the internal system because it is registered in the connected terminal table (step 151). Subsequently, the management terminal change unit 114 modifies the settings in the connected terminal table so that the information about the managed terminal corresponding to the management terminal 30 that made the logout request is linked to the administrator user to whom the request will be delegated (step 152).
[0108] Subsequently, the disconnection instruction unit 112 instructs the access point 2 to disconnect the management terminal 30 that requested the logout (step 114). The disconnection processing unit 21 in the access point 2 logs out the management terminal 30 by disconnecting it in response to this instruction (step 212).
[0109] In the first embodiment described above, when the management terminal 30 logged out, the managed terminals 40 that the management terminal 30 was managing were also logged out. However, according to this embodiment, the management terminal 30 that manages the managed terminals 40 can be kept in place, so it is not necessary to log out the managed terminals 40 along with the management terminal 30.
[0110] As a result, for example, when a managed user (e.g., managed user Y) collaborates with multiple administrators (e.g., administrators A and B), administrator A applies to the authentication system to manage managed user Y when Y visits. However, if administrator A needs to disconnect from the internal system, such as by leaving the office, in Embodiment 1, managed user Y is forced to log out. If managed user Y wishes to continue collaborating with administrator B, they would need to apply to the authentication system again to be managed by administrator B. In contrast, in this embodiment, the connected terminal table used to manage the correspondence between managed users is configured to allow managed user Y to be managed by administrator B, so managed user Y does not need to log out. Furthermore, administrators are spared the troublesome process of submitting another application.
[0111] By the way, in the above explanation, the logout request by the administrator user is made to double as an administrator user change request by specifying another administrator user. However, the administrator user may also send an administrator user change request specifying another administrator user to the authentication server 10 by performing a predetermined operation from the management terminal 30. In this case, the administrator user can delegate the management of managed users to another administrator user without logging out.
[0112] Furthermore, if an administrator manages multiple managed users, they can selectively delegate management to other administrators by specifying the managed users they wish to delegate management to in the administrator change request. When a logout request, which is also used as an administrator change request, is sent to the authentication server 10, managed users managed by that administrator but not specified in the logout request will be forcibly logged out.
[0113] Furthermore, in this embodiment, the administrator user has previously identified the administrator user to whom the managed user will delegate their authority. However, if the administrator terminal 30 used by the delegated administrator user must be connected to the company system, the administrator user may query the authentication server 10 to obtain a list of administrator users connected to the company system and specify the delegated administrator user from that list.
[0114] In each of the above embodiments, the process for logging out the managed terminal 40 has been described, but each embodiment may be combined and executed as appropriate within a non-contradictory range.
[0115] Furthermore, while the above embodiments were described using the example of integrating the authentication system into a company's internal system, the system is not limited to this example and can be applied to facilities where multiple users collaborate on a project.
[0116] In the above embodiment, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.).
[0117] Furthermore, the operation of the processor in the above embodiments may not be performed by a single processor, but may be performed by multiple processors located in physically separate locations working together. Also, the order of each processor operation is not limited to the order described in the above embodiments, but may be changed as appropriate. [Explanation of symbols]
[0118] 1 Room, 2 Access point, 3 Multifunction printer, 4 Repository, 5 LAN, 6 Beacon, 10 Authentication server, 11 Logout processing unit, 12 Storage unit, 21 Disconnection processing unit, 30 Management terminal, 31 Logout request unit, 32 Location information acquisition unit, 33 Managed terminal logout request unit, 40 Managed terminal, 41 Location information transmission unit, 111 Managed terminal identification unit, 112 Disconnection instruction unit, 113 Location relationship determination unit, 114 Management terminal change unit.
Claims
1. Equipped with a processor, The aforementioned processor, When a managed terminal used by a user who is not authorized to log in to the network system is logged into the network system under the management of an administrator user who is authorized to log in to the network system, the administrator user will, in response to a predetermined operation, identify the managed terminal to be logged out from among the managed terminals used by the user under the administrator's control. The identified managed terminal is logged out of the network system. If the predetermined operation is an operation in which the network system requests a logout from the management terminal used by the management user, and another management user is specified in the logout request, the management user of the managed user who was under the management of the management user being logged out will be changed to the other management user, thereby preventing the managed terminal used by the managed user from being logged out. An information processing device characterized by the following:
2. comprising a processor, The aforementioned processor, When a managed terminal used by a user who is not authorized to log in to the network system is logged into the network system under the management of an administrator user who is authorized to log in to the network system, the administrator user will, in response to a predetermined operation, identify the managed terminal to be logged out from among the managed terminals used by the user under the administrator's control. The identified managed terminal is logged out of the network system. If the predetermined operation is an operation in which the location information of the management terminal used by the management user is specified as a logout request, then in response to the logout request, the managed terminals that are a predetermined distance away from the management terminal are identified as targets for logout. An information processing device characterized by the following:
3. The information processing apparatus according to claim 2, characterized in that, after receiving the logout request, the processor identifies the managed terminal located at a predetermined distance from the management terminal as the target for logout.
4. On the computer, A function that, under the management of an administrator user authorized to log in to the network system, identifies a managed terminal to be logged out from among managed terminals used by a managed user under the administrator's control when the managed terminal is logged into the network system, in response to a predetermined operation by the administrator user. A function to log out the identified managed terminal from the network system. If the predetermined operation is an operation in which the network system requests a logout from the management terminal used by the management user, and another management user is specified in the logout request, the function prevents the managed terminal used by the managed user from being logged out by changing the management user of the managed user who was under the management of the management user who is logging out to the other management user. A program to achieve this.
5. A computer, A function that, under the management of an administrator user authorized to log in to the network system, identifies a managed terminal to be logged out from among managed terminals used by a managed user under the administrator's control when the managed terminal is logged into the network system, in response to a predetermined operation by the administrator user. A function to log out the identified managed terminal from the network system. If the predetermined operation is an operation in which the location information of the management terminal used by the management user is specified as a logout request, then in response to the logout request, a function is provided to identify managed terminals that are a predetermined distance away from the management terminal as targets for logout. A program to achieve this.
Citation Information
Patent Citations
Server device, information processing system and information processing method
JP2005202941A
Game device and game program
JP2011036712A
Log-in server using one-time password, method and computer readable recording medium
JP2015062139A
Communication equipment, control method therefor, and program
JP2016066217A
Guest account management using cloud based security services
US8806593B1